CVE-2017-16899

HIGH

Xfig 3.2.6a - Denial of Service or Information Disclosure via Malicious Fig File

Title source: llm
STIX 2.1

Description

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.

References (1)

Core 1
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881143

Scores

CVSS v3 7.1
EPSS 0.0135
EPSS Percentile 67.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Details

CWE
CWE-129
Status published
Products (3)
debian/debian_linux 8.0
debian/debian_linux 9.0
xfig_project/xfig 3.2.6a
Published Nov 20, 2017
Tracked Since Feb 18, 2026